Identity & Access Management Engineer

Fisher Investments

Camas (WA)

On-site

USD 100,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental and vision covered
401(k) employee match
Paid time off 20 days + 10 holidays
Family support programs
Hybrid work option

Job summary

Fisher Investments seeks an Identity & Access Management Engineer to implement Idira Privileged Access Management (PAM) rollout and run operations within the Information Security team. You will apply security expertise to configure, monitor, and optimize IAM/PAM environments and collaborate on policy and training programs.

The role requires hands-on Idira experience, SailPoint integration, and strong scripting skills.

Qualifications

  • 5+ years of hands-on experience with Idira (Idira Cloud Platform, EPM, LCD, and Idira SaaS Cloud Base)
  • 3+ years implementing enterprise-wide privileged access management across medium to large organizations
  • 3+ years as a systems engineer at a medium to large financial services company
  • 1+ years of hands-on experience with SailPoint IGA
  • Experience with password repository technologies and remote session governance
  • Excellent knowledge in IAM & PAM ecosystem
  • Strong experience installing, upgrading, configuring, operating, and troubleshooting Idira AAM and related components
  • Experience with integration of SailPoint, databases, SCIM, AWS, GCP, Azure, or Palo Alto
  • Scripting knowledge including PACLI, PowerShell, Python, JavaScript, AutoIt, REST API
  • Bachelor's degree in information assurance or related fields
  • Idira Certification (Defender and Sentry) preferred
  • Security certifications (CISSP, SSCP, CISM, SANS GSEC, ECSA, ECSP, Security+) preferred

Responsibilities

  • Onboard and provision users, store service accounts and passwords, manage credentials including interactive, non-interactive, and API-based
  • Implement PAM programs to improve security posture with measurable metrics
  • Manage configuration, administration, and maintenance of Idira solution infrastructure and application
  • Develop and maintain policies and control standards, provide documentation and training
  • Report progress and system health through KPI/risk-driven metrics
  • Address ticket queues and follow change management procedures
  • Assess risk and advise on security and process enhancements
  • Keep current with IAM/PAM technologies and industry trends and provide SME input

Skills

Idira IAM
PAM
SailPoint
PowerShell
Python
JavaScript
REST API
PACLI
AutoIt
Documentation & policy

Education

Bachelor's degree in Information Assurance/Computer Science/Cybersecurity/Information Systems

Tools

Idira AAM
EPV
PVWA
CPM
PSMP
HTML5 Gateway
PTA

Job description

The Opportunity:

The Identity & Access Management Engineer implements, coordinates, and onboards all aspects and phases of the Idira’s (formerly CyberArk) Privileged Access Management (PAM) privilege cloud solution rollout, and operational tasks. As part of the broader Information Security organization, you will apply fundamental systems security understanding, skills, and experience to maintain and operate complex information systems and security tools that satisfy organizational mission and our requirements, including partner protection needs and security requirements. You will report to the Team Lead of Identity and Access Management.

The Day-to-Day:
  • Onboard and provision users, store service accounts and password rotations, manage credentials, including those that are interactive, non-interactive, and API-based
  • Implement privileged access management programs to improve our broader security posture, demonstrated by metrics
  • Manage configuration, administration, and maintenance of Idira solution, including both the infrastructure and the application itself
  • Oversee the relevant documentation and training required for privileged access management solutions and processes, including define and help develop policies and control standards
  • Report progress and system health through metrics and KPIs that are risk-driven and operational in nature
  • Address ticket queue and follow appropriate change management procedures
  • Understand risk and make recommendations for enhancing systems security and processes
  • Keep up on current security technologies and maintain awareness of industry trends and threats, and industry best practices, providing input focusing on IAM/PAM technologies, offer subject matter expertise where relevant
Your Qualifications:
  • 5+ years of hands‑on experience with Idira (Idira Cloud Platform, EPM, LCD, and Idira SaaS Cloud Base)
  • 3+ years of experience implementing enterprise-wide privileged access management technology solution adoption across medium- to large-scale companies
  • 3+ years of experience as a systems engineer at a medium- to large-scale company in Financial Services
  • 1+ years of hands‑on experience with IGA systems such as SailPoint
  • Experience with password repository technologies and remote session governance, specifically with the policies that govern target system platforms
  • Excellent knowledge in IAM & PAM ecosystem (technology, standards, implementations, migration, and operational)
  • Strong experience installing, upgrading, configuring, operating, and troubleshooting experience with Idira AAM (CCP, CP, ASCP), EPV, PVWA, CPM, PSM, HTML5 Gateway, PSMP, PTA (with various versions)
  • Strong experience in DNA, Discovery scan and automate account onboarding process
  • Knowledge in various application integration with Idira through CPM custom plugin
  • Integration experience with SailPoint, Database, SCIM, AWS, GCP, Azure, or Palo alto
  • Scripting knowledge, PACLI, PowerShell, Python, JavaScript, AutoIt, REST API
  • Bachelor's degree in information assurance, Computer Science, Cybersecurity, Information Systems, or related field
  • Idira Certification (Defender and Sentry) is preferred
  • Security industry certification (CISSP, SSCP, CISM, SANS GSEC, ECSA, ECSP, and Security+) is preferred
Compensation:
  • $100,000 - $140,000 base salary per year in the state of WA. New hires should expect to start at the lower end of the range depending on experience
  • Eligible for a discretionary bonus based on firm and individual performance
Why Fisher Investments:

We work for a bigger purpose: bettering the investment universe. We take great pride in our inclusive culture, our learning and development framework customized for every employee, and our Great Place to Work Certification. It's the people that make the Fisher purpose possible, and we invest in them by offering exceptional benefits like:

  • 100% paid medical, dental and vision premiums for you and your qualifying dependents
  • A 50% 401(k) match, up to the IRS maximum
  • 20 days of PTO, plus 10 paid holidays
  • Family Support programs including 8 week Paid Primary Caregiver Leave, $10,000 fertility, family forming, and hormonal health assistance, and back-up child, adult, and elder care
  • This is an in-office role. Based on your role, tenure, and performance eligibility you may have the opportunity to participate in our hybrid work from home program. This program is subject to change.

FISHER INVESTMENTS IS AN EQUAL OPPORTUNITY EMPLOYER

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Identity & Access Management Engineer
Identity & Access Management Engineer

Fisher Investments • Plano (TX)

On-site
USD 120,000 - 180,000
100% paid medical, dental and vision
50% 401(k) match
20 days PTO + 10 holidays
+2
Privileged Access Engineer — IAM & PAM Expert (Hybrid)
Privileged Access Engineer — IAM & PAM Expert (Hybrid)

Fisher Investments • Plano (TX)

On-site
USD 120,000 - 180,000
100% paid medical, dental and vision
50% 401(k) match
20 days PTO + 10 holidays
+2
Identity & Access Management Engineer
Identity & Access Management Engineer

Fisher Investments • Tampa (FL)

On-site
USD 140,000 - 165,000
100% paid medical, dental and vision premiums
50% 401(k) match up to IRS maximum
20 days of PTO plus 10 paid holidays
+1
Security Services Consultant
Security Services Consultant

Palo Alto Networks • United States

Remote
MXN 700,000 - 1,000,000
Principal Engineer, Privileged Access Management
Principal Engineer, Privileged Access Management

AIG • Atlanta (GA)

On-site
USD 156,000 - 196,000
Total Rewards Program
Employee Resource Groups (ERGs)
Solutions Engineer - Enterprise Accounts, East
Solutions Engineer - Enterprise Accounts, East

Palo Alto Networks • Hartford (CT)

Hybrid
USD 198,000 - 273,000
Restricted stock units
Bonus eligibility
Flexible work environment
Associate Vice President – Information Security
Associate Vice President – Information Security

Fisher Investments • Camas (WA)

Hybrid
USD 120,000 - 180,000
100% paid medical, dental and vision
50% 401(k) match
20 days PTO + holidays
+2
Solutions Engineer - Enterprise Accounts, East
Solutions Engineer - Enterprise Accounts, East

Palo Alto Networks, Inc. • New York (NY)

On-site
USD 198,000 - 273,000
Domain Consultant 2
Domain Consultant 2

Socket.dev • Kentucky

Hybrid
USD 198,000 - 273,000
Sr. Solutions Engineer - Public Sector - SLED
Sr. Solutions Engineer - Public Sector - SLED

Palo Alto Networks • Rhode Island

On-site
USD 198,000 - 273,000
Stock options
Bonus potential
Diversity and inclusion benefits